← Bookoff Group Holdings

2026 Bookoff — member system intrusion; up to 6.43M member numbers + password hashes

2026 6.4M records affected Share on X

Data compromised

Up to ~6.43M member numbers: names, DOB, gender, email, phone, postal address, point-card/member numbers, password hashes. Payment data not held in the system.

Technical writeup

Verified company disclosure Oct 9, 2026 (Japan Cyber Watch / Kyodo) — Bookoff Group Holdings confirmed unauthorized access to a subsidiary’s member management system on October 6 and that member data was taken. Upper bound about 6.43 million member numbers (not necessarily unique people). Fields: names, dates of birth, gender, emails, phones, postal addresses, point card and member numbers, and password hashes described as encrypted/unreadable as-is. Payment data not stored in the system. Bookoff blocked attackers, fixed a vulnerability, blocked external access, reported to Japan’s Personal Information Protection Commission, and is reviewing systems. No misuse published at indexing.

Root cause

Unauthorized access to a subsidiary member-management system (confirmed Oct 6); vulnerability later fixed; data taken externally

References